Exeon Analytics
Swiss AI-powered network detection and response platform built on metadata, not full packet capture
Quick Overview
| Company | Exeon Analytics AG |
|---|---|
| Category | SIEM & Security Monitoring |
| Headquarters | Zurich, Switzerland |
| EU Presence | Switzerland (adequacy decision, outside the EEA) |
| Open Source | No |
| Pricing | Custom quote scoped to network size; no published price list, demo on request |
| Free Option | Demo on request |
| Replaces | Darktrace, Vectra AI, ExtraHop |
Detailed Review
Exeon Analytics is a Zurich-based network detection and response platform that builds behavioural baselines from network metadata rather than full packet capture, which keeps sensitive payload contents out of the analysis pipeline while still surfacing lateral movement, command-and-control traffic and ransomware behaviour across on-premises, private-cloud and public-cloud environments.
The company began as a spin-off from ETH Zurich, and the platform layers user and entity behaviour analytics on top of the same metadata stream rather than requiring a second, separate data collection effort to run alongside it.
Where the SIEM and EDR products in this category detect from logs and endpoint agents, Exeon detects from the network itself, which matters when a compromised system cannot be trusted to report on itself or cannot run an agent at all — OT equipment and unmanaged devices are the obvious cases.
That makes it a complement to a SIEM rather than a replacement for one, and it is priced and sold accordingly, on a per-deployment quote rather than a published tier.
Exeon does not publish pricing; every engagement starts with a demo and a quote scoped to network size, rather than a plan comparison, which suits an enterprise sales motion more than a self-serve one. Hosting and processing stay in Switzerland, which sits outside the EU but is treated as data-protection adequate — worth noting for organisations to whom EU membership itself, not just adequacy, is the actual requirement.
What Exeon Analytics does well
- Metadata-based NDR, no packet payload capture
- UEBA layered on the same data stream
- Deployable on-prem, private or public cloud
- ETH Zurich engineering pedigree
- Sees traffic agents and logs miss (OT, unmanaged devices)
Where Exeon Analytics falls short
- No published pricing — quote only
- Complements a SIEM rather than replacing one
- Newer and smaller than Darktrace or Vectra AI
- Switzerland is adequacy-based, not EU membership
Standout feature. Detects from network metadata alone, so devices too old or too locked-down to run an agent are still covered.
Pros and Cons
Pros
- Metadata-based NDR, no packet payload capture
- UEBA layered on the same data stream
- Deployable on-prem, private or public cloud
- ETH Zurich engineering pedigree
- Sees traffic agents and logs miss (OT, unmanaged devices)
Cons
- No published pricing — quote only
- Complements a SIEM rather than replacing one
- Newer and smaller than Darktrace or Vectra AI
- Switzerland is adequacy-based, not EU membership
Alternatives to Exeon Analytics
Frequently Asked Questions
What is Exeon Analytics?
Exeon Analytics is a Zurich-based network detection and response platform that builds behavioural baselines from network metadata rather than full packet capture, which keeps sensitive payload contents out of the analysis pipeline while still surfacing lateral movement, command-and-control traffic and ransomware behaviour across on-premises, private-cloud and public-cloud environments.
The company began as a spin-off from ETH Zurich, and the platform layers user and entity behaviour analytics on top of the same metadata stream rather than requiring a second, separate data collection effort to run alongside it.
Where is Exeon Analytics based?
Exeon Analytics operates from Zurich, Switzerland, which places it under Switzerland (adequacy decision, outside the EEA).
What does Exeon Analytics cost?
Custom quote scoped to network size; no published price list, demo on request. Demo on request.
Who is Exeon Analytics best for?
Network-level detection where agents cannot run. Detects from network metadata alone, so devices too old or too locked-down to run an agent are still covered.
What are the drawbacks of Exeon Analytics?
No published pricing — quote only. Complements a SIEM rather than replacing one. Newer and smaller than Darktrace or Vectra AI. Switzerland is adequacy-based, not EU membership.